CVE-2026-87121

9.8

lwIP · TCP/IP Stack MQTT

The lwIP TCP/IP Stack MQTT implementation is vulnerable to an out-of-bounds write, which may allow an unauthenticated attacker to achieve remote code execution on the affected device.

Executive summary

A critical out-of-bounds write vulnerability in the lwIP TCP/IP Stack MQTT implementation allows unauthenticated remote code execution, posing a severe risk to device integrity.

Vulnerability

The vulnerability is identified as an out-of-bounds write (CWE-787) within the MQTT component of the lwIP stack. This flaw allows an unauthenticated, network-adjacent attacker to corrupt memory and execute arbitrary code on the target system.

Business impact

Successful exploitation of this vulnerability results in full system compromise, enabling an attacker to gain control over the affected device. Given the critical CVSS score of 9.8 and the potential for remote code execution, this represents a severe risk to operational continuity, data confidentiality, and the integrity of embedded systems relying on this stack.

Remediation

Immediate Action: Update the lwIP TCP/IP Stack MQTT implementation to the latest version, ensuring the integration of the fix associated with commit identifier f89407ea711879c04d91c92b35d67be78bbaf0f1.

Proactive Monitoring: Monitor network traffic for unusual MQTT protocol patterns and review system logs for signs of unexpected process crashes or unauthorized execution attempts.

Compensating Controls: Implement network segmentation and firewall rules to restrict access to the MQTT service to only trusted, necessary endpoints, thereby reducing the attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention. Organizations utilizing the lwIP TCP/IP stack should verify their versions and prioritize the application of the vendor-provided patch. Failure to remediate this vulnerability leaves devices exposed to full remote takeover by unauthenticated attackers.

More lwIP CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Shahriyar Jalayeri of ByteRay Ltd. reported this vulnerability to CISA., per the CVE Program record.